Docs: What tends to follow?
Documentation / Query & analyse

What tends to follow?

See what happened next during an incident, and how quickly.

What tends to follow? shows, for an incident, what happened next: which event followed which in the incident’s timeline, and how quickly. Use it to see how an incident unfolded and which early signs came before the errors.

Using it

  1. Open an incident and select the What tends to follow? tab. You can also reach it from a service’s page in Services, which lists that service’s incidents.
  2. Read the list from the top. Each entry shows one event in the timeline and the event that followed it, with the time between them. The closest-following pairs come first.
  3. If the tab says there is not enough timeline, the incident does not yet have enough events to show what followed what.

Things to keep in mind

  • Order is not cause. One event following another does not prove that the first caused the second. Confirm anything important with Search or SQL.
  • Combine it with What changed? to see which log patterns moved during the same period.